IT Security Governance Manager

HLB

Petaling Jaya

On-site

MYR 180,000 - 300,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Hong Leong Bank seeks a Technical Governance Manager specializing in Network Security Controls to oversee policy, compliance and risk management for perimeter defenses.

You will ensure firewalls, WAFs, proxies, VPNs, and NAC systems comply with banking regulations and internal standards, with continuous auditing and measurable KRIs across the control stack.

Qualifications

  • 5+ years in cybersecurity, technical risk, or IT audit.
  • Deep understanding of firewall architectures, WAFs, proxies and enterprise VPNs.
  • Experience auditing policies within Cisco ISE for enterprise WiFi.
  • Familiarity with NSPM tools used for policy management and compliance mapping.
  • Clear banking regulatory knowledge including PCI-DSS and data protection standards.

Responsibilities

  • Define and maintain the Bank’s security standards aligned with NIST, PCI-DSS, ISO/IEC 27001, SOC 2 and CIS Benchmarks.
  • Review and update policies for Web Application Firewalls, proxies, VPNs, and NAC systems.
  • Lead audit readiness and remediation tracking for security findings and vulnerabilities.
  • Report KRIs on control effectiveness to Internal, Paynet and bank regulators.
  • Govern WAF deployments, API security baselines, SSL/TLS decryption profiles, and false-positive management.
  • Govern Cisco ISE for enterprise WiFi, 802.1X, device profiling, and endpoint posture.

Skills

Cybersecurity
Network Security
Risk & Audit
NAC Policy
PCI-DSS knowledge

Tools

NSPM tools

Job description

If you are looking to excel and make a difference, take a closer look at us…

Overview

We are seeking a Technical Governance Manager specializing in Network Security Controls to oversee the policy, compliance, and risk management frameworks governing our bank’s perimeter defenses.

In this role, you will act as the ultimate authority on what the security rules should be, ensuring our Firewalls, WAFs, Proxies, VPN infrastructure, and Wireless Access Networks strictly adhere to banking regulations and internal security standards. You will ensure that every rule, policy, network access pathway, and application defense mechanism is justified, documented, regularly reviewed, and fully compliant with financial sector mandates.

Responsibilities
  • Security Framework Alignment: Define and maintain the Bank’s technical security standards, aligning them with industry frameworks (e.g., NIST, PCI-DSS, ISO/IEC 27001, SOC 2, CIS Benchmarks).
  • Policy & Standard Engineering : Review and update technical security policies, baselines, and procedures for Web Application Firewalls (WAF), Web Proxies, Enterprise VPNs, and Network Access Control (NAC) systems and other security devices.
  • Audit & Compliance Remediation: Lead technical readiness for internal and external audits. Work directly with teams to track, prioritize, and validate the remediation of security findings and vulnerabilities.
  • Metrics & Reporting: Report and track Internal, Paynet & BNM regulatory Key Risk Indicators (KRIs) regarding control effectiveness.
  • WAF & Application Layer Governance: Define the governance framework for Web Application Firewall (WAF) deployments. Establish standards for rule tuning, core rule sets (e.g., OWASP Top 10 mitigation), API security baselines, SSL/TLS decryption profiles, and the management of false-positive thresholds to protect critical banking applications.
  • WiFi & Network Access Control (NAC) Governance: Define and audit the security architectures within Cisco ISE governing corporate, guest, and BYOD wireless networks. Establish strict baselines for 802.1X authentication, device profiling, and endpoint posture assessment before network admission.
  • Firewall Rule Lifecycle Governance: Define the mandatory review intervals and lifecycle processes for firewall rules. Oversee the automated or manual recertification of rule base to eliminate legacy, overly permissive, or unused rules.
  • Proxy & Content Filtering Governance: Establish governance frameworks for URL categorization, SSL decryption policies, data loss prevention (DLP) integration at the proxy level, and the formal approval process for proxy bypasses.
  • VPN & Remote Access Compliance: Ensure VPN configurations, multi-factor authentication (MFA) mandates, and conditional access policies align with Zero Trust principles and banking regulatory standards.
  • Assurance & Continuous Auditing: Utilize network assurance and compliance tools to continuously audit configurations against established golden images and security compliance baselines.
  • Exception Management & Risk Acceptance: Formally evaluate, risk-score, and manage the lifecycle of technical exception requests (e.g., emergency port openings, WAF rule bypasses for specific legacy applications, or non-compliant wireless device onboarding), ensuring temporary risks are tracked and mitigated.
  • Regulatory & Audit Liaison: Serve as the primary subject matter expert during internal, external, and central bank/regulatory audits concerning network perimeter security, application protection, and network access controls.
Skills & Experience We Are Looking For
  • Experience: 5+ years in cybersecurity, technical risk, or IT audit
  • Perimeter & Application Security Expertise: Deep conceptual and technical understanding of firewall architectures Web Application Firewall, secure web gateways/proxies and enterprise VPN platforms.
  • Identity & NAC Expertise: Proven experience auditing or defining policies within Cisco ISE (Identity Services Engine) for enterprise WiFi management, including certificate-based authentication and guest network segmentation.
  • Network Auditing Tools: Strong familiarity with Network Security Policy Management (NSPM) tools used for rule optimization and compliance mapping.
  • Regulatory Knowledge: Clear understanding of banking-specific compliance requirements related to network segmentation, application layer security, wireless security, and data protection (e.g., PCI-DSS compliance for public-facing web applications).
Preferred Qualifications
  • Certifications: CISA /CRISC/ CISSP, or technical networking/security certifications (not mandatory)
  • Mindset: A highly analytical, detail-oriented professional who values strict documentation and process-repeatable outcomes over quick operational fixes.

About Hong Leong Bank

We are a leading financial institution in Malaysia backed by a century of entrepreneurial heritage. Providing comprehensive financial services guided by a Digital-at-the-Core ethos has earned us industry recognition and accolades for our innovative approach in making banking simpler and more effortless for our customers. Our digital and physical offerings span across a vast nationwide network in Malaysia, strengthened with an expanding regional presence in Singapore, Hong Kong, Vietnam, Cambodia, and China.

We seek to strike a balance between diversity, inclusion and merit to achieve ourmission of infusing diversity in thinking and skillsets into our organisation.Candidatesare assessed based on merit and potential, in line with our mission to attract and recruit the best talent available.Expanding on our “Digital at the Core” ethos, we are progressively digitising the employee journey and experience to provide a strong foundation for our people to drive life-long learning, achieve their career aspirations and grow talent from within our organisation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Governance Manager
IT Security Governance Manager

Hong Leong Bank • Petaling Jaya

On-site
MYR 180,000 - 240,000
IT Security Governance Manager
IT Security Governance Manager

Hong Leong Bank Berhad • Petaling Jaya

On-site
MYR 180,000 - 280,000
Senior Security Advisor - Technical Project Manager
Senior Security Advisor - Technical Project Manager

Hong Leong Bank • Shah Alam

On-site
MYR 180,000 - 260,000
Application ID Administrator
Application ID Administrator

Hong Leong Bank Berhad • Selangor

On-site
MYR 120,000 - 180,000
Application ID Administrator
Application ID Administrator

HLB • Petaling Jaya

On-site
MYR 180,000 - 240,000
Application Support Manager
Application Support Manager

Hong Leong Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 160,000
Manager, Network Security Operations
Manager, Network Security Operations

Hong Leong Bank Berhad • Selangor

On-site
MYR 120,000 - 180,000
Assistant Manager / Senior Executive - Risk Management (Regional Risk)
Assistant Manager / Senior Executive - Risk Management (Regional Risk)

HLB • Kuala Lumpur

On-site
MYR 180,000 - 260,000
Exec / Sr Exec / Asst Manager / Manager - Personal Financial Services Credit (Compliance)
Exec / Sr Exec / Asst Manager / Manager - Personal Financial Services Credit (Compliance)

Hong Leong Bank Berhad • Kuala Lumpur

On-site
MYR 120,000 - 180,000
Assistant Manager - Payments, Partnerships, Fintech & Ecosystems (Business Intelligence & Reporting Analyst)
Assistant Manager - Payments, Partnerships, Fintech & Ecosystems (Business Intelligence & Reporting Analyst)

HLB • Kuala Lumpur

On-site
MYR 90,000 - 150,000